IP Library Granted Patent US 12,406,259
Granted Patent B2
US 12,406,259 · App. 17/418,862 · Granted Sep 2, 2025

Fraud detection system, fraud detection method and program

Inventor: Kyosuke Tomoda (Tokyo, JP)
Assignee: RAKUTEN GROUP, INC.
G06Q20/4016G06N20/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,406,259
App. No.
17/418,862
Granted
Sep 2, 2025
Kind
B2
Abstract

A fraud detection system includes at least one processor configured to acquire, based on an action performed by each of a plurality of users, a score relating to a fraud level of the user, determine, based on the score of each of the plurality of users, an acquisition method for a feature amount of the user such that an acquisition time of the feature amount becomes shorter as the fraud level becomes lower, acquire the feature amount of each of the plurality of users based on the acquisition method determined for the user, and detect fraud made by each of the plurality of users based on the feature amount of the user.

Claims (82)

1. A fraud detection system, comprising:

a fraud detection server comprising at least one processor configured to:

acquire information that indicates actions performed by each of a plurality of users of a service provided over the internet;

acquire, based on an action performed by each of the plurality of users of the service, a score relating to a fraud level of the each of the plurality of users;

wherein the action and the score correspond to actions conducted by the plurality of users on the service provided over the internet;

wherein the actions each include an action content comprising an action type, an IP address, an access location, an access date and time, a URL of an accessed page, and a user operation content;

wherein the action type comprises a user registration, a login, or a page transition;

wherein the IP address is the IP address of a user terminal used for the action;

wherein the access location is the location of a user or the user terminal;

determine, based on the score of each of the plurality of users, an acquisition method for a feature amount of the each of the plurality of users such that an acquisition time of the feature amount becomes shorter as the fraud level becomes lower;

wherein the feature amount is information on a feature for each of the plurality of users and is related to actions by each of the plurality of users on the service provided over the internet;

acquire the feature amount of each of the plurality of users based on the acquisition method determined for the each of the plurality of users;

detect, in real time, fraud made by each of the plurality of users based on the feature amount of the each of the plurality of users;

wherein the at least one processor is configured to acquire a plurality of types of feature amounts,

wherein the acquisition method is the type of the feature amount to be acquired,

wherein the at least one processor is configured to determine the type of the feature amount for each of the plurality of users such that the acquisition time becomes shorter as the fraud level becomes lower,

wherein the at least one processor is configured to acquire the feature amount of the type determined for each of the plurality of users;

wherein each of the plurality of types of feature amounts is acquirable in parallel with each other,

wherein the at least one processor is configured to acquire the feature amount of the type determined for each of the plurality of users and the feature amount of a type having a shorter acquisition time than the acquisition time of the determined type;

restrict a processing requested by the user based on the detection;

receive a request from each of the plurality of users,

set the acquisition method based on the score of each of the plurality of users and a number of requests from each of the plurality of users such that the acquisition time becomes shorter as the fraud level becomes lower and the acquisition time as a whole falls within a predetermined range, and

determine the acquisition method for each of the plurality of users based on the score of the each of the plurality of users and the set acquisition method.

2. The fraud detection system according to claim 1 , wherein the at least one processor is configured to determine a length relating to the acquisition time for each of the scores, and to set the acquisition method based on the determined length.

3. The fraud detection system according to claim 1 , wherein the at least one processor is configured to create a distribution relating to a relationship between the score and the number of requests, and to set the acquisition method based on the created distribution.

4. The fraud detection system according to claim 1 ,

wherein the at least one processor is configured to:

acquire, based on each of a plurality of actions performed by each of the plurality of users, an individual score relating to the fraud level of the each of the plurality of actions performed by the each of the plurality of users,

acquire, based on the individual scores of each of the plurality of users, an overall score relating to an overall fraud level of the each of the plurality of users, and

determine the acquisition method for each of the plurality of users such that the acquisition time becomes shorter as the fraud level of the overall score becomes lower.

5. The fraud detection system according to claim 4 , wherein the at least one processor is configured to acquire the overall score of each of the plurality of users further based on a decision tree in which each of the individual scores of the each of the plurality of users is a variable.

6. The fraud detection system according to claim 1 , wherein the at least one processor is configured to determine the acquisition method for each of the plurality of users such that the feature amount important in fraud detection is acquired and the acquisition time becomes shorter as the fraud level becomes lower.

7. The fraud detection system according to claim 1 ,

wherein the at least one processor is configured to acquire the score of each of the plurality of users based on a first action performed by the each of the plurality of users, and

wherein the at least one processor is configured to detect fraud made by each of the plurality of users based on the feature amount of the each of the plurality of users when a second action after the first action is performed by the each of the plurality of users.

8. The fraud detection system according to claim 7 ,

wherein the first action is an action up to a request for payment,

wherein the second action is the request for the payment, and

wherein the at least one processor restricts execution of the payment by, among the plurality of users, a user for which fraud has been detected.

9. A fraud detection system, comprising:

a fraud detection server comprising at least one processor configured to:

acquire information that indicates actions performed by each of a plurality of users of a service provided over the internet;

acquire, based on an action performed by each of the plurality of users of the service, a score relating to a fraud level of the each of the plurality of users;

wherein the action and the score correspond to actions conducted by the plurality of users on the service provided over the internet;

wherein the actions each include an action content comprising an action type, an IP address, an access location, an access date and time, a URL of an accessed page, and a user operation content;

wherein the action type comprises a user registration, a login, or a page transition;

wherein the IP address is the IP address of a user terminal used for the action;

wherein the access location is the location of a user or the user terminal;

determine, based on the score of each of the plurality of users, an acquisition method for a feature amount of the each of the plurality of users such that an acquisition time of the feature amount becomes shorter as the fraud level becomes lower;

wherein the feature amount is information on a feature for each of the plurality of users and is related to actions by each of the plurality of users on the service provided over the internet;

acquire the feature amount of each of the plurality of users based on the acquisition method determined for the each of the plurality of users;

detect, in real time, fraud made by each of the plurality of users based on the feature amount of the each of the plurality of users;

wherein the at least one processor is configured to acquire the plurality of types of feature amounts,

wherein the acquisition method is a time limit within which the feature amount is permitted to be acquired,

wherein the at least one processor is configured to determine the time limit for each of the plurality of users such that the time limit becomes shorter as the fraud level becomes lower,

wherein the at least one processor is configured to acquire the feature amount of each of the plurality of users based on the time limit determined for the each of the plurality of users;

restrict a processing requested by the user based on the detection;

receive a request from each of the plurality of users,

set the acquisition method based on the score of each of the plurality of users and a number of requests from each of the plurality of users such that the acquisition time becomes shorter as the fraud level becomes lower and the acquisition time as a whole falls within a predetermined range, and

determine the acquisition method for each of the plurality of users based on the score of the each of the plurality of users and the set acquisition method.

10. A fraud detection system, comprising:

a fraud detection server comprising at least one processor configured to:

acquire information that indicates actions performed by each of a plurality of users of a service provided over the internet;

acquire, based on an action performed by each of the plurality of users of the service, a score relating to a fraud level of the each of the plurality of users;

wherein the action and the score correspond to actions conducted by the plurality of users on the service provided over the internet;

wherein the actions each include an action content comprising an action type, an IP address, an access location, an access date and time, a URL of an accessed page, and a user operation content;

wherein the action type comprises a user registration, a login, or a page transition;

wherein the IP address is the IP address of a user terminal used for the action;

wherein the access location is the location of a user or the user terminal;

determine, based on the score of each of the plurality of users, an acquisition method for a feature amount of the each of the plurality of users such that an acquisition time of the feature amount becomes shorter as the fraud level becomes lower;

wherein the feature amount is information on a feature for each of the plurality of users and is related to actions by each of the plurality of users on the service provided over the internet;

acquire the feature amount of each of the plurality of users based on the acquisition method determined for the each of the plurality of users;

detect, in real time, fraud made by each of the plurality of users based on the feature amount of the each of the plurality of users;

a first machine learning model configured to acquire an individual score of a first user;

wherein the first machine learning model is trained with first training data in which a feature amount of each action by the first user is an input and the individual score is an output;

a second machine learning model configured to acquire an overall score;

wherein the second machine learning model is trained with second training data in which a plurality of individual scores of a second user are inputs and information indicating whether or not the second user is fraudulent is the output;

a third machine learning model configured to detect fraud wherein a feature amount of a third user is input into the third machine learning model;

restrict a processing requested by the user based on the detection;

receive a request from each of the plurality of users,

set the acquisition method based on the score of each of the plurality of users and a number of requests from each of the plurality of users such that the acquisition time becomes shorter as the fraud level becomes lower and the acquisition time as a whole falls within a predetermined range, and

determine the acquisition method for each of the plurality of users based on the score of the each of the plurality of users and the set acquisition method.

Assignments (2)
CHANGE OF NAME Recorded Jul 13, 2021
From: RAKUTEN, INC.
To: RAKUTEN GROUP, INC.
Reel/Frame 056845/0831 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 28, 2021
From: TOMODA, KYOSUKE
To: RAKUTEN, INC.
Reel/Frame 056680/0651 →
Continuity (1)
Related Publication 20220309510A1 · Sep 29, 2022
References Cited (52)
US 9031877B1 · Santhana · 2015 [cited by examiner]
US 9135467B2 · Mishra · 2015 [cited by examiner]
US 10204374B1 · Holan · 2019 [cited by examiner]
US 10825028B1 · Kramme · 2020 [cited by examiner]
US 11062315B2 · Noble · 2021 [cited by examiner]
US 11151569B2 · Allbright · 2021 [cited by examiner]
US 11570195B2 · Madhu · 2023 [cited by examiner]
US 11580339B2 · Warrick, II · 2023 [cited by examiner]
US 11722459B1 · Hall · 2023 [cited by examiner]
US 11741374B1 · Difranco · 2023 [cited by examiner]
US 20050076230A1 · Redenbaugh · 2005 [cited by examiner]
US 20070133768A1 · Singh · 2007 [cited by examiner]
US 20070192484A1 · Yamaoka et al. · 2007 [cited by applicant]
US 20100185534A1 · Satyavolu · 2010 [cited by examiner]
US 20110055074A1 · Chen · 2011 [cited by examiner]
US 20110191200A1 · Bayer · 2011 [cited by examiner]
US 20110270752A1 · Neto · 2011 [cited by examiner]
US 20120158540A1 · Ganti · 2012 [cited by examiner]
US 20130024375A1 · Choudhuri et al. · 2013 [cited by applicant]
US 20130133258A1 · Carter · 2013 [cited by examiner]
US 20150039513A1 · Adjaoute · 2015 [cited by examiner]
US 20150238672A1 · Barrett · 2015 [cited by examiner]
US 20160005029A1 · Ivey · 2016 [cited by examiner]
US 20170235792A1 · Mawji · 2017 [cited by examiner]
US 20170270529A1 · Ebel · 2017 [cited by examiner]
US 20170330175A1 · Bayer · 2017 [cited by examiner]
US 20180218261A1 · Myara · 2018 [cited by examiner]
US 20180253728A1 · Hanis · 2018 [cited by examiner]
US 20180365696A1 · Yan · 2018 [cited by examiner]
US 20190065596A1 · Meron · 2019 [cited by examiner]
US 20190095608A1 · Kohli · 2019 [cited by examiner]
US 20190188799A1 · Kumar · 2019 [cited by examiner]
US 20190259037A1 · Kimura · 2019 [cited by applicant]
US 20190295088A1 · Jia · 2019 [cited by examiner]
US 20200007564A1 · Xie · 2020 [cited by examiner]
US 20200118136A1 · Zhang · 2020 [cited by examiner]
US 20200272849A1 · Tomoda · 2020 [cited by applicant]
US 20200364718A1 · Hindi · 2020 [cited by examiner]
US 20210012346A1 · Walters · 2021 [cited by examiner]
US 20210042757A1 · Hearty · 2021 [cited by examiner]
US 20210312455A1 · Venturelli · 2021 [cited by examiner]
US 20220172213A1 · Hearty · 2022 [cited by examiner]
JP 2003248661A · 2003 [cited by applicant]
JP 2006260201A · 2006 [cited by applicant]
WO 2010044288A1 · 2010 [cited by applicant]
WO 2019049210A1 · 2019 [cited by applicant]
J.-M. Liu, J. Tian, Z.-X. Cai, Y. Zhou, R.-H. Luo and R.-R. Wang, “A hybrid semi-supervised approach for financial fraud detection,” 2017 International Conference on Machine Learning and Cybernetics (ICMLC), Ningbo, Chi… [cited by examiner]
E. Caldeira, G. Brandao and A. C. M. Pereira, “Fraud Analysis and Prevention in e-Commerce Transactions,” 2014 9th Latin American Web Congress, Minas Gerais, Brazil, 2014, pp. 42-49. (Year: 2014). [cited by examiner]
Microsoft Computer Dictionary, Fifth Edition, Microsoft Press, 2002, p. 281. (Year: 2002). [cited by examiner]
N. Rtayli and N. Enneya, “Credit Card Risk Detection based on Feature-Filter and Fraud Identification,” 2019 Third International Conference on Intelligent Computing in Data Sciences (ICDS), Marrakech, Morocco, 2019, pp.… [cited by examiner]
Search Report of Dec. 9, 2021, for corresponding EP Patent Application No. 20900760.8 pp. 1-9. [cited by applicant]
International Search Report for PCT/JP2020/037003, pp. 1-9 (see the transmittal letter). [cited by applicant]